2023-04-21 14:44:17 +00:00
{
"type" : "bundle" ,
"id" : "bundle--5825c994-18b0-4900-a73d-4558950d210f" ,
"objects" : [
{
"type" : "identity" ,
"spec_version" : "2.1" ,
"id" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-02T08:12:26.000Z" ,
"modified" : "2017-01-02T08:12:26.000Z" ,
"name" : "CIRCL" ,
"identity_class" : "organization"
} ,
{
"type" : "report" ,
"spec_version" : "2.1" ,
"id" : "report--5825c994-18b0-4900-a73d-4558950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-02T08:12:26.000Z" ,
"modified" : "2017-01-02T08:12:26.000Z" ,
"name" : "OSINT - BlackNurse Denial of Service Attack" ,
"published" : "2017-01-11T20:17:22Z" ,
"object_refs" : [
"observed-data--5825ca2c-85d0-4193-8f68-4311950d210f" ,
"url--5825ca2c-85d0-4193-8f68-4311950d210f" ,
"observed-data--5825ca60-9220-4be6-9181-42fd950d210f" ,
"url--5825ca60-9220-4be6-9181-42fd950d210f" ,
"indicator--5825ca78-5058-4247-b218-4139950d210f" ,
"indicator--5825ca87-c1b4-4257-842a-4133950d210f" ,
"observed-data--586a0b44-3b80-433c-9069-3b4ebce2ab96" ,
"file--586a0b44-3b80-433c-9069-3b4ebce2ab96" ,
"artifact--586a0b44-3b80-433c-9069-3b4ebce2ab96" ,
"x-misp-attribute--582af62b-a4a4-46b6-bee0-441b950d210f" ,
"observed-data--586a0b6a-224c-45d7-a53f-4060bce2ab96" ,
"url--586a0b6a-224c-45d7-a53f-4060bce2ab96"
] ,
"labels" : [
"Threat-Report" ,
"misp:tool=\"MISP-STIX-Converter\"" ,
"ecsirt:availability=\"ddos\"" ,
"europol-incident:availability=\"dos-ddos\"" ,
"osint:source-type=\"blog-post\""
] ,
"object_marking_refs" : [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--5825ca2c-85d0-4193-8f68-4311950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-11-11T13:39:56.000Z" ,
"modified" : "2016-11-11T13:39:56.000Z" ,
"first_observed" : "2016-11-11T13:39:56Z" ,
"last_observed" : "2016-11-11T13:39:56Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--5825ca2c-85d0-4193-8f68-4311950d210f"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--5825ca2c-85d0-4193-8f68-4311950d210f" ,
"value" : "http://www.netresec.com/?page=Blog&month=2016-11&post=BlackNurse-Denial-of-Service-Attack"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--5825ca60-9220-4be6-9181-42fd950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-11-11T13:40:48.000Z" ,
"modified" : "2016-11-11T13:40:48.000Z" ,
"first_observed" : "2016-11-11T13:40:48Z" ,
"last_observed" : "2016-11-11T13:40:48Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--5825ca60-9220-4be6-9181-42fd950d210f"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--5825ca60-9220-4be6-9181-42fd950d210f" ,
"value" : "http://soc.tdc.dk/blacknurse/blacknurse.pdf"
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5825ca78-5058-4247-b218-4139950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-11-11T13:41:12.000Z" ,
"modified" : "2016-11-11T13:41:12.000Z" ,
"pattern" : "[alert icmp $EXTERNAL_NET any -> $HOME_NET any (msg:\"TDC-SOC - Possible BlackNurse attack from external source \"; itype:3; icode:3; detection_filter:track by_dst, count 250, seconds 1; reference:url, soc.tdc.dk/blacknurse/blacknurse.pdf; metadata:TDC-SOC-CERT,18032016; priority:3; sid:88000012; rev:1;)]" ,
"pattern_type" : "snort" ,
2023-12-14 14:30:15 +00:00
"pattern_version" : "2.1" ,
2023-04-21 14:44:17 +00:00
"valid_from" : "2016-11-11T13:41:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"snort\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5825ca87-c1b4-4257-842a-4133950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-11-11T13:41:27.000Z" ,
"modified" : "2016-11-11T13:41:27.000Z" ,
"pattern" : "[alert icmp $HOME_NET any -> $EXTERNAL_NET any (msg:\"TDC-SOC - Possible BlackNurse attack from internal source\"; itype:3; icode:3; detection_filter:track by_dst, count 250, seconds 1; reference:url, soc.tdc.dk/blacknurse/blacknurse.pdf; metadata:TDC-SOC-CERT,18032016; priority:3; sid:88000013; rev:1;)]" ,
"pattern_type" : "snort" ,
2023-12-14 14:30:15 +00:00
"pattern_version" : "2.1" ,
2023-04-21 14:44:17 +00:00
"valid_from" : "2016-11-11T13:41:27Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"snort\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--586a0b44-3b80-433c-9069-3b4ebce2ab96" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-02T08:11:48.000Z" ,
"modified" : "2017-01-02T08:11:48.000Z" ,
"first_observed" : "2017-01-02T08:11:48Z" ,
"last_observed" : "2017-01-02T08:11:48Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--586a0b44-3b80-433c-9069-3b4ebce2ab96" ,
"artifact--586a0b44-3b80-433c-9069-3b4ebce2ab96"
] ,
"labels" : [
"misp:type=\"attachment\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--586a0b44-3b80-433c-9069-3b4ebce2ab96" ,
"name" : "Blacknurse_v.1.7.pdf" ,
"content_ref" : "artifact--586a0b44-3b80-433c-9069-3b4ebce2ab96"
} ,
{
"type" : "artifact" ,
"spec_version" : "2.1" ,
"id" : "artifact--586a0b44-3b80-433c-9069-3b4ebce2ab96" ,
"payload_bin" : " J V B E R i 0 x L j U N C i W 1 t b W 1 D Q o x I D A g b 2 J q D Q o 8 P C 9 U e X B l L 0 N h d G F s b 2 c v U G F n Z X M g M i A w I F I v T G F u Z y h k Y S 1 E S y k g L 1 N 0 c n V j d F R y Z W V S b 290 I D Y w I D A g U i 9 N Y X J r S W 5 m b z w 8 L 0 1 h c m t l Z C B 0 c n V l P j 4 v T W V 0 Y W R h d G E g M z g z I D A g U i 9 W a W V 3 Z X J Q c m V m Z X J l b m N l c y A z O D Q g M C B S P j 4 N C m V u Z G 9 i a g 0 K M i A w I G 9 i a g 0 K P D w v V H l w Z S 9 Q Y W d l c y 9 D b 3 V u d C A 2 L 0 t p Z H N b I D M g M C B S I D I 3 I D A g U i A z N i A w I F I g M z k g M C B S I D Q y I D A g U i A 0 N S A w I F J d I D 4 + D Q p l b m R v Y m o N C j M g M C B v Y m o N C j w 8 L 1 R 5 c G U v U G F n Z S 9 Q Y X J l b n Q g M i A w I F I v U m V z b 3 V y Y 2 V z P D w v R m 9 u d D w 8 L 0 Y x I D U g M C B S L 0 Y y I D k g M C B S L 0 Y z I D E x I D A g U i 9 G N C A x M y A w I F I v R j U g M T U g M C B S L 0 Y 2 I D I x I D A g U j 4 + L 0 V 4 d E d T d G F 0 Z T w 8 L 0 d T N y A 3 I D A g U i 9 H U z g g O C A w I F I + P i 9 Y T 2 J q Z W N 0 P D w v S W 1 h Z 2 U y N i A y N i A w I F I + P i 9 Q c m 9 j U 2 V 0 W y 9 Q R E Y v V G V 4 d C 9 J b W F n Z U I v S W 1 h Z 2 V D L 0 l t Y W d l S V 0 g P j 4 v Q W 5 u b 3 R z W y A y M C A w I F J d I C 9 N Z W R p Y U J v e F s g M C A w I D U 5 N S 41 I D g 0 M i 4 y N V 0 g L 0 N v b n R l b n R z I D Q g M C B S L 0 d y b 3 V w P D w v V H l w Z S 9 H c m 91 c C 9 T L 1 R y Y W 5 z c G F y Z W 5 j e S 9 D U y 9 E Z X Z p Y 2 V S R 0 I + P i 9 U Y W J z L 1 M v U 3 R y d W N 0 U G F y Z W 50 c y A w P j 4 N C m V u Z G 9 i a g 0 K N C A w I G 9 i a g 0 K P D w v R m l s d G V y L 0 Z s Y X R l R G V j b 2 R l L 0 x l b m d 0 a C A z N D Q 1 P j 4 N C n N 0 c m V h b Q 0 K e J y 9 X E t z 3 D Y S v q t K / 4 F H M l V D 4 U 3 Q 5 U p V Z D t e 5 + m 1 t Z u D K w d J l m S v L Y 1 j T 7 K V f 77 H 7 W 6 A M x y C I D g z G O t A D Q k S / a H R b 4 A 8 + + 7 z 6 v 3 t 5 f W q e P z 47 L v V 6 v L 63 c 3 b 4 s 3 Z + X K 1 W t 7 / f n b x 96 e b s 5 e X d + 8 f L l f v l w 9 n r / + 8 W u G l 75 f L 1 c 3 n b 78 t z p 8 + K f 44 P W E 1 w z 9 r G 1 W w Q r e 61 o V V o h a 6 + H x z e v L b N 8 X D 6 c n 5 x e n J 2 f e 84 B y v X 9 y e n n C 4 m R W 80 L K t 20 L z 2 h Y X 93 D T 89 d N c f c F u i 3 u 6 M z 6 s + e n J 2 / K o v q 9 u P j h 9 O Q Z d P f P 0 5 O 51 H e 4 N Q U U D g w b 7 j 3 C g 4 E V z 35 + U h R n L 3 E W f n 7 y 4 m n B z n 66 f L g r y p u H x f P z K h + f m a m t L R r V 1 K Z J 4 Q 9 A 8 e O C Y k 3 N 5 c 6 g x O G g R C F M L Z p t V A a k k c k t V D V r m S h Y L T g e p Y G e 7 k Y v v 4 o i X w P j V v C m E A r E q X E c g H 8 t w L M 9 e P 1 x S j + 0 N Z 1 G w l G b l k A s N A 6 s a Y G 5 h W 5 q C y e I 34319 p s N 9 c k b Q 6 q q o 1 p Y b u p G F C A 5 s h D A T D H o u / + U 3 k z D D H p x y Q C q U t R J R Q v o m z V q R 3 g W 6 C Y f a J j O N q l e Y 8 C t x 6 B l L d c I l J J 100 T m c / r O c E L b j o I b l n 9 O S p D / A r R j S G F L / d m G Q 3 P I O h b J Q h p n L f s q 31 F v a + W m l y O j O D K q W I B w g 0 J d X L 8 p B e M p m 8 S z g e K C g W 0 f x f S m N C k c I h 8 O x e t W x o B E p O h s 7 c j P 4 Y w e Q H e 6 h s H q Z t o k d K b I i z t g E D I i Q 1 w O V S X x 8 J S y N J Z 3 w 5 y h L B v u e p I d e y f x q o 2 P + N f r K p i o R F d x 9 K J R N b M z h 7 A z P c G h e S A a t q 2 F K B r D a i V 2999676 H b U E p b V S s b g 3 J R L T g v 38 F R l z d J X C Y j L g F 2 H m x Z B N d 5 J c u P g K o t L + l 4 X T X l h 1 + q h Z D l n w T 2 c 8 V N + a X i T X m T Q t 1 k R C 0 h z L B R b i Y Z a H N C A T k 3 M g b l u 2 q h y t W q U n 0 G p u C 1 + 8 I b U Q G p b d 3 u r Q K C H c k U d B 5 N m Z r v H l k L f i R Y y p D J 1 w y U Y n d U 4 r j M U m B C 5 v E K a d p a g y i o h q a f W 43 W B y L h c Z M v Z A x 6 s h s H W x V t P c w I p E M N 1 n 5 k i v 9 N R u S m W k g F R m Q h W r Q i q n x f g V F Z P o S u Y H 8 c k M r I J o o j 7 j i F U p B f e 4 p C M x S M O A N V J K 9 K 9 h L F 7 W + O 4 O Y B i w 6 h B C y K E a q z E m p q H R 1 S k 5 O S E b W N j m l W U E g P r F W P Y T 8 U F d K h C w q T 7 V 5 u X T u 3 o M F y + w 4 B 5 k D G O 0 A W s H U H n g d b d 6 B Z 4 P E O E s 3 d A B y P q c k Z o A G + a L v v P 9 o + N E j G O E 4 k D J J O G K R 4 N 0 m D Z G y t u s I J i c N T N D q X l R T l C u x R U y 6 j 5 m c P q h b Y N 0 Y 0 a X g c r a T h M d O G J 95 L 0 v A E k G 1 M Q f c i Q j Y n o B E 1 N 3 v R c O Y m x f s D i b Q g V s c m A u a M N U c n o i B O G S E C A T / o x v K v C n I U 57 H v 6 c o V n h h w 3 / k w S G Y x m j 7 u Q C V n m D 0 k i Y Q R X p N D v y S X W C M d k s c i J c y x r + O k C i j C Z o E i w X h v a Y h r + X z X / R q t z Y 47 z J 4 r m f S F r n 3 C F 8 Y 66 H y h a 5 / w h V E E H q H j l H N W Y k h 9 v N H 3 P N 449 H E S 2 N l 5 C d F Q y h i x 3 m 3 C z U 32 l P R 0 Y G O N 7 g v 4 k 2 p h I a H v 3 B 2 F 3 J u 4 + 7 a y 7 s d 1 J W X f I a a i 8 v 1 Q c k 7 w Q p R J 10 j 0 / P x P 8 l d 2 N d j O p 2 m O C 2 c g R j i B c r r C L X m g Y p O E J w p f H f X 1 S D n J k N y o m j 975 c t B g p U / 4 e E l V V k e F Z V o s J Y A V 36 u t C 7 P 0 R Q / q w Q v X y X s h B S 5 B i G Z I r M 1 d x C D W e x 4 Q N S V B S D I / w n u y 9 z c V w J t 3 b B A H P A 6 x V C V D R d Y X Y w c x n H 9 V k F + / A 88 v A B c y u F 8 l g K n s 4 F r A d w W 0 2 b 6 S G n y C R w n g Q s g L F I Q Q j d 9 g M x j p L A 7 F 0 L 3 v D e E Z p w L 31 e L x t V f l 9 V C l / d J S G 0 2 S F K i D g 8 Q 4 U K U 0 o o C G M 4 S Y B T L B g a 8 d j v G n z o F I Z t 5 l 8 p g 8 r u 7 l K h 8 x h l r i 2 M Q f i G n Q R L y F 9 k R H 8 B f Y S T Q l d 8 S K L N Z Y o l r d P u o k 8 p m d B V j r g g b F 94 Z 0 b f a y 86 O x E B K z J C b X g C k W v C + P W K J + F J 1 x p j T 4 i G 6 a Q 0 M Q M O u U Y d F C x E v F + s e R j 2 x 6 p n T G f S j Y 11 T 7 s V 7 W y s l F o I b Y S G 4 A a c H w Y 1 J B j f K Z k I m G a V B 48 i S w t n m 5 Q 8 Y t E 2 A d W g y Z j S u + 8 S T M d c + k Y z F O u i S M d c + k Y z F O s B m O 4 H Q s z L e f z d E Y j a 19 H j d G 0 G 0 3 Q O M t g / T O g h Y j V z n O W p C 73 R s Q 9 q 8 r p K J n a D l z 57 F u M C M z a 2 j U N 6 G q d x 2 O l d g d G s h 0 l 1 I f / m u 4 q J 8 t 6 I L B a 5 T v k Q v 4 T p Z + k o o P b r 8 G M 389 h w H B 3 e l 5 M g 4 R j Y B 7 E B J j 1 D S Y p T S Y y Y b 9 W 3 u Y W k I B M a m 57 B h j V J q x y m R I L h J p u n M T 7 k x 5 M M D y i R T D 7 c V S I 2 T I V c k 3 K G M M A f R a K 7 i 9 j A k 2 R 5 u v O P Z N Z P r a Q x h M c M R 7 C K H 0 K q 8 / n T 5 s E E c W 2 O e 1 V k 6 R + 6 z E K / T j k 365 X z P O 0 w 6 V q t K l p / w 16 M z s C q i x K M s / w v H Z u t Y U 8 R 5 W 5 H F c a V i 2 i 4 C d m h V 0 5 N L Z 3 L g 6 l 2 l o B 8 t 6 c d H u n t Z G V Z e I Z 1 L N F X u I t 3 z B Y O F 95 V k d D e d O Q y r j y h u n 1 L z H l v u 3 o m L Y T D H Z 5 i 0 D V / X P N c k c U a g R m 95 u G n X L h u M E + K u 3 b V P u P Z Y B 51 r d + 0 T r j 3 W Q e f a 4 + 0 u S o r 23 w 3 R T Y T z z W r M t 8 d v 8 B D j N w y 8 u w S N t 3 p W 1 V b H F v v n d Z W 0 I U w C 8 p 4 E / Q a i b T q r + q H i N m 7 V 9 y V t L U 7 I k P C n b o E H C W M 4 s W X Z X f b 4 N j s W L j V l 9 N t o Y A 4 Z V 26 f 69 X f K Q X X + 0 3 K i F J z B b J q Q 96 k 7 L q n N 6 d K r c 2 k O U r 0 l D b q Q + h U S q R F 7 y c F p l n P K 8 l 7 l a Q / 0 e K S e a d W V 3 Z 25 v W 1 u z q + F D c L p x k r C / C W S l w D n O M h 2 o E 8 k W A F V H I 2 c 9 B p x u j 0 W J + d o q J M 6 S s M z b 0 O E x A i 4 f g V E 4 n 8 Y z M G t w x / h b E Z W 48 M L T s d / 4 S 0 L d j d t F U Z D w C 4 w F A j H g C 49 o k A I N Z B F w C 49 o k A I I r A I f T s i e f m E z c 4 C h M 3 D P 0 3 U 7 i t 0 t t 3 y 2 m J L 2 J v m + l V 10 R X K f 8 t I U N i W y H g i w q 86 M N f F W e Y S 3 M s x a 63 U k z 4 z z 1 h c C Z q L k Z g J F 2 W I + j n e 5 q F d t p l T f e U 1 o s A O 63 Q O Y 49 o J 2 h w 9 / k l I q q 9 S t l l C Z Q C 6 U E d C C X 9 j D p t + a A j f k t E P 8 A 7 K T j 2 p c z E t I E P s a Z g 4 Y
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--582af62b-a4a4-46b6-bee0-441b950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-11-15T11:48:59.000Z" ,
"modified" : "2016-11-15T11:48:59.000Z" ,
"labels" : [
"misp:type=\"comment\"" ,
"misp:category=\"External analysis\""
] ,
"x_misp_category" : "External analysis" ,
"x_misp_type" : "comment" ,
"x_misp_value" : "\u00e2\u20ac\u0153We recommend that you grant permission for the ICMP unreachable message type (type 3). Denying ICMP unreachable messages disables ICMP Path MTU discovery, which can halt IPSec and PPTP traffic. See RFC 1195 and RFC 1435 for details about Path MTU Discovery.\u00e2\u20ac\u009d"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--586a0b6a-224c-45d7-a53f-4060bce2ab96" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2017-01-02T08:12:26.000Z" ,
"modified" : "2017-01-02T08:12:26.000Z" ,
"first_observed" : "2017-01-02T08:12:26Z" ,
"last_observed" : "2017-01-02T08:12:26Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--586a0b6a-224c-45d7-a53f-4060bce2ab96"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--586a0b6a-224c-45d7-a53f-4060bce2ab96" ,
"value" : "http://www.blacknurse.dk/"
} ,
{
"type" : "marking-definition" ,
"spec_version" : "2.1" ,
"id" : "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ,
"created" : "2017-01-20T00:00:00.000Z" ,
"definition_type" : "tlp" ,
"name" : "TLP:WHITE" ,
"definition" : {
"tlp" : "white"
}
}
]
}